Splunk Search

How to delete fields name

shashi584
Explorer

I want to delete this field (VID) from one of my search query, this is not available under  Field extractions.

and what is the difference between (a and #) ?

shashi584_1-1633796036005.png

 

Labels (1)
0 Karma

shashi584
Explorer

I have extracted one field with the same name and I have deleted it, so I'm wondering why it's still displaying in the fields section. As you mentioned I have used the same field in search query hence it is showing which makes sence. 

Is there any way to remove/unhide completely from the field section without removing field data from the search query?

 

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Ok, you lost me now 🙂

If you're using the field as part of your SPL search you need it processed, right? So you wouldn't want to remove the extraction because then you'd lose the ability to match on this field or calculate values based on it.

If you want simply to remove a field from being included in your search results, you can use the very surprisingly called 😉 command - fields

So add

 

| fields - yourfield yourotherfield ...

 

And the fields will be removed from the result set.

Of course the original event will still be visible unless you remove the _raw field.

Other than that - there is no possibility that I know of to keep the field in the result set and not show it in fields list. Remember that the fields list is populated automaticaly from the fields discovered during processing the search (see previous remarks about fast vs. verbose mode) which are presemt in sufficiently high percentage of results.

So if you had a field which would be set in just one of your 10k result events, it wouldn't show. But if half of your events contains a particular field, it will show up here.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

What do you mean by " this is not available under Field extractions"?

The field is being discovered either because it's used in the search or  you're using verbose mode.

The difference between a and # is that one is text field, the other is nummerical.

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...